Are AI phone calls illegal? The honest answer
The short answer: it depends on who's calling whom. When an AI phone assistant answers incoming calls for your business, meaning customers who are calling you anyway, that's generally allowed. You're simply using a modern tool to stay reachable instead of letting callers land on voicemail. If you want to clarify what this solution even is first, our AI phone assistant page explains the definition and how it works.
It gets tricky in the other direction: outbound marketing calls to private individuals without their explicit consent are heavily restricted in Germany, regardless of whether a human or an AI is calling. So if you're considering an AI answering service that picks up for you, you're on solid ground. If you want to cold-call using AI, you're not. This page covers the first case.
What GDPR compliance actually means on the phone
GDPR compliance isn't a label a product comes with on its own. It results from how the provider and the business work together. Four points matter most in practice:
- Data processing agreement (DPA): If the provider processes caller data on your behalf, you need a DPA under Article 28 GDPR. It states what happens to the data, who the subprocessors are, and where processing takes place.
- Data storage in the EU: Look for servers in Germany or the EU. That saves you the extra hurdles of a third-country data transfer.
- Data minimization: Only what you actually need is captured: who called, what it was about, how urgent it is. A full audio recording usually isn't necessary at all.
- Privacy policy: Using the assistant belongs transparently in your privacy policy and in your records of processing activities.
Checklist: a GDPR-compliant AI phone assistant in 5 points
You can recognize a GDPR-compliant AI phone assistant by five checkable points: a data processing agreement under Article 28 GDPR, a server location in Germany or the EU, documented technical and organizational measures (TOMs), call recording only with consent (Section 201 of the German Criminal Code), and a transparent AI notice under Article 50 of the EU AI Act. Work through the list with every provider before you book:
- Ask for a data processing agreement (DPA). If the provider processes caller data on your behalf, you need a DPA under Article 28 GDPR. It states what happens to the data, who the subprocessors are, and where processing takes place. If a provider doesn't offer a DPA, the review ends there.
- Confirm the server location: Germany or the EU. Ask specifically where voice data, transcripts and summaries are processed and stored, including subprocessors, for example for speech recognition or telephony. EU processing saves you the extra hurdles of a third-country transfer.
- Have the TOMs shown to you. The technical and organizational measures under Article 32 GDPR, such as encryption, access control and retention periods, belong as an attachment to the DPA. A serious provider discloses them instead of just writing "GDPR compliant" on their website.
- Recording only with consent. Section 201 of the German Criminal Code makes it a criminal offense to record a private conversation without authorization, so a call recording needs the consent of everyone involved, usually through a notice and confirmation at the start of the call. Check whether the assistant stores audio at all or only keeps a structured summary; the data-minimal option is the simpler path.
- Does it meet the AI transparency duty? Since August 2, 2026, Article 50 of the EU AI Act requires that callers learn when an AI is speaking. Call the provider's demo or test number and listen to the first sentence: does the assistant introduce itself as an AI? Details are in EU AI Act and AI phone assistants.
You settle points 1 through 3 in writing with the provider; points 4 and 5 you check yourself on the phone. The recording section further below shows how to additionally verify that the answers match practice, and keep in mind: this checklist is a starting point, not legal advice.
Transparent AI notice: what the EU AI Act expects
The EU AI Act requires, among other things, that people be able to recognize when they're talking with an AI system. For your phone assistant, that simply means: it introduces itself as an AI at the start of the call, for example "Hello, this is the digital assistant for company XY." That's not tedious fine print, it builds trust. Callers tend to respond more calmly when they know what they're dealing with from the start, instead of feeling deceived.
Since August 2, 2026, this transparency duty (Article 50 of the AI Act) has been binding; the Digital Omnibus did not push it back. What exactly applies, which deadlines the Omnibus changed, and how a business implements the duty is covered in the companion article EU AI Act and AI Phone Assistants: What's Applied Since August 2, 2026.
For more on how such an assistant behaves in conversation and where the line to voicemail runs, see AI answering service. And for the topic from the caller's perspective, when an AI call is legitimate and when it's a scam, see AI phone calls: allowed, recognizable, explained.
Recording and consent: only as much as necessary
Many people automatically associate "AI on the phone" with a recording. That doesn't have to be the case. Often a structured summary of the request is enough, without storing the call as audio, which is data-minimal and the legally simpler route. If a call is recorded, that needs a legal basis and, as a rule, a clear notice right at the start of the call. When in doubt: better to collect less data than too much.
Data storage in Germany and the EU
For businesses in the DACH region, server location is a central point. When caller data is processed within the EU, ideally in German or European data centers, you stay within a familiar legal framework. Ask the provider specifically about location and the subprocessors involved, and have it confirmed in the DPA. We check exactly this together during setup when you use our AI phone assistant.
Note: this is not legal advice
This article explains the topic in general, accessible terms and does not replace legal advice. Data protection always depends on the specific case, on your industry, your processes, and exactly what data arises. For a binding assessment, consult a data protection officer or a specialized attorney. We support you with the technical implementation and provide the building blocks you need for it. For professionals bound by confidentiality, such as tax practices under Section 203 of the German Criminal Code, the article Will AI Replace Tax Advisors? covers confidentiality on the phone.